Associate - Healthcare Privacy and Compliance
BakerHostetler · Ohio, United States · 1 mo ago
Hybrid$235k–$285k/yrFull-time
About the role
BakerHostetler is seeking a junior-to-mid-level associate (2–4 years of experience) to join its nationally recognized Healthcare Privacy and Compliance team within the Digital Assets and Data Management (DADM) Practice Group.
Responsibilities
- Advise healthcare organizations on privacy and cybersecurity incidents, including ransomware attacks, business email compromises, insider threats, and other data security events.
- Coincide and manage incident response efforts involving forensic investigators, notification vendors, crisis communications professionals, and law enforcement.
- Conduct breach assessments and counsel clients regarding state and federal notification obligations.
- Aid healthcare clients with investigations and inquiries from federal and state regulators, including the U.S. Department of Health and Human Services Office for Civil Rights (OCR) and state attorneys general.
- Counsel clients on HIPAA Privacy Rule and Security Rule compliance and broader privacy and data governance obligations.
- Develop and conduct incident response preparedness programs, tabletop exercises, and privacy and cybersecurity training.
- Advising clients on emerging issues involving artificial intelligence, digital health technologies, and evolving privacy regulations.
- Collaborate with lawyers across BakerHostetler's nationally recognized privacy, cybersecurity, healthcare, litigation, and regulatory practices.
Qualifications
- Strong academic credentials.
- Excellent legal research, writing, analytical, and communication skills.
- The ability to manage multiple matters in a fast-paced environment.
- Sound judgment and strong problem-solving abilities.
- A demonstrated interest in privacy, cybersecurity, healthcare, technology, investigations, or regulatory matters.
- A collaborative approach and desire to work as part of a nationally integrated team.
Preferred Qualifications
- HIPAA privacy and security experience.
- Incident response or cybersecurity counseling experience.
- Experience working with healthcare industry clients.
- Prior government, regulatory, judicial clerkship, or Am Law 200 experience.
- Privacy certifications such as CIPP/US or related credentials.